■■■■□ 🚨 Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree
Google says an undercover Mandiant analyst infiltrated TeamPCP’s inner circle as the hacking group compromised open-source software and ultimately breached more than 1,000 companies.
⠀
The analyst gained access to TeamPCP’s core “CanisterWorm” chat in March, joining a group of roughly 12 members and watching the operation from the inside.
⠀
The mole also gained access to a server containing credentials stolen from victims, including usernames, passwords, and access tokens.
Google used that visibility to alert cloud and technology providers, revoke compromised credentials, and send hundreds of notifications to affected organizations.
⠀
The operation also exposed a TeamPCP member developing an AI-assisted zero-day capable of bypassing two-factor authentication in widely used login software.
Google obtained the exploit code, verified that it worked after minor modifications, and privately notified the developer so the vulnerability could be patched.
⠀
TeamPCP’s campaign compromised hundreds of open-source packages and affected organizations including GitHub, Mistral AI, Mercor, the European Commission, and employee devices at OpenAI.
⠀
Google says operational security mistakes later helped investigators identify an alleged TeamPCP member, with information passed to the FBI.
Two Australians accused of being principal participants in TeamPCP were arrested last month.
